Back to Home
Legal & Platform Policies

Privacy Policy

Learn how NexusBlog protects, processes, and respects user personal data under GDPR and CCPA standards.

Last updated: October 3, 2026Verified Policy

Privacy Policy

Effective Date: October 2, 2026
Last Revised: October 2, 2026

At NexusBlog (operated by the Nexus Engineering Group, "we", "our", or "us"), we are deeply dedicated to transparency, data minimization, and protecting your digital privacy. This Privacy Policy details how we gather, process, retain, and safeguard personal information when you access our technical publications, interact with our architecture blueprints, subscribe to our technical dispatch, or register for a developer account.

We adhere strictly to international data privacy regulations, including the General Data Protection Regulation (GDPR) (EU/EEA), the UK General Data Protection Regulation (UK GDPR), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).


1. Principles of Data Processing

We operate on three foundational privacy engineering principles:

  1. Data Minimization: We only collect information strictly necessary to provide high-performance reading experiences, secure authentication, and relevant engineering dispatches.
  2. Zero Commercial Monetization: We never sell, rent, monetize, or trade your personal data, reading patterns, or contact details to third-party ad networks, data brokers, or marketing syndicates.
  3. Defense-in-Depth Security: All collected tokens, hashes, and session metrics are protected by modern cryptographic safeguards and strict access controls.

2. Categories of Information We Collect

A. Information You Explicitly Provide

  • Account Credentials: When creating an account, we collect your name, chosen username, email address, and an Argon2id cryptographic hash of your password. We never store plaintext passwords.
  • Author & Contributor Profiles: If you publish or submit technical blueprints, we store your profile biography, social profile links (e.g., GitHub, Twitter, LinkedIn, personal website), and uploaded profile avatar.
  • Community Contributions & Comments: When participating in technical article discussions, we record your comments, timestamps, edit history, and associated article IDs.
  • Newsletter Subscription: When opting into the Weekly Engineering Dispatch, we collect your email address solely to deliver weekly distributed systems case studies and architecture analyses.

B. Automatically Collected Technical & Telemetry Data

  • Authentication & Security Logs: IP address, browser user-agent, correlation IDs, login timestamps, and session revocation records required to prevent account hijacking, credential stuffing, and unauthorized access.
  • Reading Progress & Dashboard History: When authenticated, your bookmark collections and scroll progress across technical series are persisted to synchronize your reading session across desktop and mobile devices.
  • Diagnostic Telemetry: Coarse server request metrics (HTTP status codes, latency in milliseconds, route endpoints) used strictly to diagnose latency spikes, broken routes, and upstream database bottlenecks.

3. Lawful Basis for Processing (GDPR/UK GDPR)

We process your personal information under the following legal bases:

  • Contractual Necessity (Article 6(1)(b)): To create and maintain your user account, authenticate API requests, and deliver user-requested features like bookmarks and draft saves.
  • Legitimate Interests (Article 6(1)(f)): To secure our API infrastructure against DDoS attacks, optimize database query performance, and ensure platform availability.
  • Consent (Article 6(1)(a)): For sending weekly newsletter dispatches, which you can withdraw at any time via a single-click unsubscribe link.
  • Legal Compliance (Article 6(1)(c)): To maintain audit trails and comply with valid legal obligations or statutory mandates.

4. Third-Party Service Providers & Cloud Infrastructure

We partner only with security-audited infrastructure providers who maintain SOC 2 Type II, ISO 27001, or equivalent certifications:

  • Database & Hosting Infrastructure: Managed cloud instances with TLS 1.3 encryption-in-transit and AES-256 encryption-at-rest.
  • Transactional & Dispatch Email Delivery: Brevo (Sendinblue) for sending account verification codes, password reset links, and newsletter dispatches under strict Data Processing Agreements (DPAs).
  • Object Storage: S3-compatible secure object storage for hosting user avatars and architecture diagrams.

5. Cookies & Local Storage

We utilize strictly necessary session cookies and local storage items:

  • refreshToken & nexus_access_token: Cryptographically signed JSON Web Tokens (JWT) used to maintain secure authentication state.
  • nexus-theme: Local storage preference storing your dark/light UI mode selection.
  • We do not use third-party analytics pixels, advertising trackers, or cross-site tracking beacons.

For complete details, please consult our Cookie Policy.


6. Data Retention & Erasure Policy

  • Active Accounts: Your account profile, reading history, and saved bookmarks are retained for as long as your account remains active.
  • Account Deletion: If you delete your account, your personal identification records, session tokens, and reading logs are permanently purged within 30 days. Publicly published collaborative articles may be reassigned to an archived staff pseudonym to preserve technical archive integrity.
  • Server Telemetry Logs: Security audit logs and HTTP access logs are automatically rotated and purged after 90 days.

7. Your Rights & Data Protection Controls

Depending on your jurisdiction (such as under GDPR or CCPA), you have the right to:

  • Right to Access & Portability: Request a machine-readable export (JSON) of your personal data and activity records.
  • Right to Rectification: Update or correct your profile information at any time via Dashboard Settings.
  • Right to Erasure ("Right to Be Forgotten"): Request permanent deletion of your account and personal identifiers.
  • Right to Restrict or Object: Object to legitimate interest processing or withdraw email newsletter consent instantly.
  • Non-Discrimination: We will never deny services, degrade quality, or alter pricing because you exercised your privacy rights.

To submit a data access or deletion request, please reach out directly to privacy@nexusnation.in or submit our Contact Form.


8. Children's Privacy

NexusBlog is an engineering and technical platform intended for software engineers, system architects, and professionals. We do not knowingly collect personal information from individuals under the age of 16. If you believe a minor has registered an account, contact us immediately for prompt removal.


9. Revisions & Notifications

We may revise this Privacy Policy periodically to reflect architectural changes or regulatory updates. Substantial amendments will be highlighted through an announcement banner on the platform and detailed in our Engineering Dispatch.

Contact Privacy Office:
Nexus Engineering Group
Email: privacy@nexusnation.in
Inquiries: Contact Page